跳至主要内容
29B
data points captured on Purple
±3-7%
corrected accuracy vs camera
80,000+
venues running Purple
< 60s
dashboard freshness

TL;DR / Key Takeaways

  • WiFi analytics has two modes: presence (anonymous, sensor-based) and engagement (identified, captive-portal-based). Most venues need both, with each answering a different question.
  • MAC randomisation changed the discipline. Platforms that adapted use statistical correction and consented identification to maintain ±3-7% accuracy versus camera ground truth. Platforms that ignored the change have lost accuracy.
  • The headline metrics are footfall, dwell time, return-visit rate, zone transitions, new-vs-returning split, and capture rate. The honest reading is the corrected figure with the confidence interval, not the raw probe count.
  • GDPR-compliant analytics is achievable with hashed MAC and rotation for presence, explicit consent at the portal for engagement, a DPIA, and clear venue signage. the ICO and the EU's CNIL have both issued positive guidance on the model.
  • The strongest sector applications are retail, shopping malls, airports, stadiums, museums, and corporate offices. Each uses the same data model with a different framing layer on top.

Most venues are sitting on a sensor network they have already paid for: the access points they put in for guest WiFi. The same hardware, the same RF events, the same association logs, used differently, produce a usable account of who walked in, how long they stayed, where they went, and whether they came back.

That is WiFi analytics. It is not a perfect substitute for a turnstile counter at the door or a computer-vision camera on the till. It is a much cheaper substitute that covers the whole venue rather than one chokepoint, and that surfaces movement and dwell data the cameras cannot produce.

This guide is the operating reference for venue and marketing teams considering or running WiFi analytics. It covers the two modes (presence and engagement), the metrics that matter, what MAC randomisation broke and how the discipline adapted, the comparison against alternative people-counting technologies, the UK GDPR shape, and the sector applications that work.

The two modes: presence and engagement

Almost every confused conversation about WiFi analytics is the result of mixing these two up. They use different data, answer different questions, and run under different legal bases.

Presence analytics

Anonymous, sensor-based, derived from probe requests and association logs. Counts unique devices in a zone over a time window. Hashed MAC with rotation as the technical privacy control.

Answers: how many people came in, how long they stayed, how they moved between zones, and whether overall volume is up or down.

Lawful basis: legitimate interest with DPIA, signage, opt-out.

Engagement analytics

Identified, captive-portal-based, derived from sign-ins and ongoing sessions. Ties visits to a contact record. The substrate for segmentation, journeys, and lifecycle marketing.

Answers: who came in, how often they come, what time of day, which sites of a multi-site brand, and the marketing-actionable cohort behaviour.

Lawful basis: explicit consent at the portal sign-in.

Most venues need both. Presence gives the headline footfall and dwell numbers, comparable like-for-like across sites. Engagement gives the identified cohort that marketing can actually run journeys against. The two are joined at the captive portal: a visitor who signs in moves from the presence dataset to the engagement dataset for that visit.

MAC randomisation and why it changed the discipline

For most of the 2010s, WiFi analytics rested on a quietly false assumption: that a device’s MAC address was stable across visits. iOS 14 (2020) broke that for iPhones. Android 10 broke it for Android. Windows 11 and macOS Sonoma extended the change to laptops. By 2026, the great majority of consumer devices present a randomised, rotating MAC during probe requests before association.

Naive counting that treated each unique MAC as a unique device started over-counting. Return-visit rates collapsed; new-visitor share rocketed; cohort retention curves stopped making sense.

The discipline adapted in two ways. First, statistical correction: probabilistic models that account for the expected randomisation rate and rotation cadence per device class, calibrated against camera ground truth at known sites. Second, identification through the captive portal: visitors who sign in present a stable identity that survives randomisation entirely.

The combined accuracy of a corrected presence stream plus an opted-in engagement layer in 2026 is comparable to where 2018 footfall analytics sat, with a stronger privacy story. The vendors that did the correction work have maintained accuracy; the vendors that did not have lost it. Worth checking explicitly during evaluation.

Free tool

Want to see how MAC rotation affects your metrics? Use our free MAC Randomization Simulator (from our free WiFi tools library) to model raw device counts, ground truth visitor counts, and the reconciled counts.

The randomisation timeline

  • 2014: iOS 8 introduces randomised probes (off by default in practice).
  • 2020: iOS 14 randomises per-SSID by default.
  • 2020: Android 10+ randomises per-SSID by default.
  • 2022: Windows 11 expands to all WLAN probes.
  • 2023: macOS Sonoma matches iOS behaviour on laptops.
  • 2026: randomisation is the dominant assumption; static MAC is the edge case.

The six metrics worth reporting

WiFi analytics platforms can produce a hundred derived metrics. Six of them carry almost all the decision weight.

Footfall

Unique visitors entering a defined zone in a time window. The headline KPI for retail and venue operators.

Reported daily, weekly, monthly. Comparable like-for-like.

Dwell time

Median, p25/p75, p95 time-in-zone per visit. Distinguishes browsers from buyers.

Median by sector; trend is what matters most.

Return-visit rate

Share of visitors in a window who also visited in the previous N days. Loyalty signal.

18-32% in retail; 45-60% in transit and corporate.

Zone transitions

Origin-destination flows between defined zones. The basis for journey analytics and layout testing.

Used in malls, airports, museums, large retail.

New vs returning

Acquisition vs retention split. Useful for marketing attribution and for honest reporting of footfall lift.

70/30 to 50/50 typical, depending on category.

Capture rate

Share of detected presence converting to a captive-portal sign-in. Bridge between presence and engagement.

15-40% depending on portal design and incentive.

WiFi vs cameras vs door sensors

WiFi analytics is not the only people-counting technology. The right answer for most venues uses two of them together: a high-accuracy chokepoint counter at the front door and WiFi across the whole venue for dwell and journey.

MethodAccuracyCoverageCostPrivacyJourneys
WiFi presence±3-7%Whole venueUses existing APsHashed MAC, opt-out, signageNative
Computer vision±1-3% at doorwayField of view onlyPer-camera + computeStrongest concern in EULimited
Door sensor (IR / 3D)±2-4%Doorway onlyPer-doorLowNone

Compliance: UK GDPR, CNIL, CCPA, ISO 27001

WiFi analytics that respects privacy is a solved problem. The model below is what the CNIL has explicitly approved and what the ICO has consistently allowed. Pizza Express, AGS Airports, and the University of Sheffield all run venue analytics on Purple.

UK GDPR

Presence analytics: legitimate interest with DPIA. Engagement analytics: explicit consent at the portal. Hashed MAC with rotation is the accepted technical control for presence.

Reference ›

CNIL guidance

The French regulator has issued specific guidance on WiFi analytics. The model that satisfies the CNIL is the one the rest of the EU follows.

Reference ›

CCPA / CPRA

California requires a privacy notice and opt-out mechanism. WiFi analytics that aggregates and anonymises sits within the existing privacy-policy framework.

Reference ›

ISO 27001

Annex A.5.34 (privacy and protection of PII) and A.5.12 (classification of information) apply. The platform should produce a DPIA template and a retention-schedule export.

Reference ›

The four operational requirements: a completed DPIA, hashed MAC with rotation for the presence stream, explicit consent at the captive portal for the engagement stream, and visible venue signage explaining what is being measured and how to opt out. Purple ships templates and venue-signage assets for each. The compliance posture is part of the product, not an afterthought.

How to evaluate a WiFi analytics platform

An eight-item checklist for procurement, operations, and the data team.

✓Statistical correction for MAC randomisation

A platform that does not correct for randomised MACs is not measuring footfall in 2026. Ask for the methodology and the validation against camera ground truth.

✓Both presence and engagement modes

You need the anonymous, whole-venue mode and the consented, identified mode. Platforms that only do one of them aren't enough.

✓Zone configuration without recabling

Zone definitions should be edited in the dashboard, not by re-pulling cable. Coverage areas, anchor stores, departments.

✓Like-for-like comparable framing

Multi-site operators need normalised KPIs across sites of different size and traffic profile. Raw numbers do not work.

✓Live BI export

Hourly batch to S3 / BigQuery / Snowflake. Native Looker / Tableau connectors. The data should land where your analysts already work.

✓DPIA template and signage assets

The platform should hand you the privacy paperwork and the venue signage you need. Building it from scratch slows deployment by weeks.

✓Hardware independence

Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, Fortinet. The analytics layer should outlive the AP refresh.

✓Auditable retention controls

Configurable retention by data class. Identifiable data on the shortest defensible schedule. Aggregate data on whatever your reporting needs.

Frequently asked questions

What is WiFi analytics?

+

WiFi analytics is the practice of using a venue's existing wireless network as a sensor for footfall, dwell time, and customer movement. Two modes: presence analytics (anonymous, sensor-based, MAC-randomisation-affected) and engagement analytics (identified, captive-portal-based, opted-in). Most operators run both, with each answering a different question.

How accurate is WiFi footfall counting?

+

Modern WiFi analytics with statistical correction for MAC randomisation runs at ±3-7% versus camera-based ground truth in retail environments. The accuracy is good enough for like-for-like comparison, trend tracking, and benchmarking; it is not good enough for cash-register reconciliation. The number you report should be the corrected figure with the confidence interval, not the raw probe count.

Has MAC randomisation broken WiFi analytics?

+

It changed it. iOS 14+, Android 10+, Windows 11, and macOS Sonoma randomise the MAC address presented in probe requests before association. Naive counting that treated each unique MAC as a unique device is now wrong. Statistical correction models, plus opted-in captive-portal identification for engagement analytics, are how modern platforms maintain accuracy. The platforms that ignored the change have lost accuracy; the ones that adapted have not.

What is the difference between presence and engagement analytics?

+

Presence analytics counts devices that are physically present but not authenticated; it measures footfall and dwell anonymously and is GDPR-defensible under legitimate interest with a DPIA. Engagement analytics measures behaviour for visitors who signed in to the captive portal and gave consent; it ties visits to identity, supports segmentation, and runs under explicit consent. Most venues need both.

Is WiFi analytics GDPR-compliant?

+

Yes, with proper design. For presence analytics, hash the MAC client-side with rotation, document a legitimate-interest assessment, complete a DPIA, and post visible signage. For engagement analytics, run on explicit consent at the captive portal. the ICO and the EU's CNIL have both issued positive guidance on WiFi analytics where these conditions are met. We have a full compliance playbook linked from this pillar.

Is WiFi or camera better for people counting?

+

Different jobs. Cameras with computer vision are more accurate at single-doorway counting (95%+ vs ground truth) but cost more, see only their field of view, and raise stronger privacy concerns. WiFi covers the whole venue cheaply, supports dwell and zone-to-zone analysis natively, and identifies returning visitors statistically. Most large-format retail and venue operators run both: cameras at the door for accuracy, WiFi inside for coverage.

What sort of dwell time should I expect?

+

Median dwell across Purple's dataset: 9-14 minutes in QSR, 35-55 minutes in casual dining, 18-32 minutes in apparel retail, 55-95 minutes in shopping malls, 75-130 minutes in airports air-side. Useful as benchmarks; the more useful measure is your own dwell trend month-on-month against same-store comparable.

Can WiFi analytics track customer journeys?

+

Within a venue, yes. Zone-to-zone transitions, time-in-zone, common paths, and drop-off points are all measurable. Across venues of the same brand, it depends on whether the visitor authenticated (engagement) or not (presence); presence-only journeys across sites are very weak signal once MAC randomisation is accounted for.

Does WiFi analytics work for office occupancy?

+

Yes. The same infrastructure that authenticates staff devices reports utilisation by floor, by day-of-week, and by hour-of-day. Integration with workplace booking systems (Robin, Envoy, Microsoft Places) is a common pattern. Office occupancy is one of the higher-confidence use cases because the population is largely authenticated and the device count is more stable than retail footfall.

How does this integrate with my existing BI stack?

+

Direct API access, hourly batch export to S3 / BigQuery / Snowflake, native Looker and Tableau connectors, and webhook event streaming. The data model is documented and stable. Most large operators land WiFi data into the same warehouse as POS and loyalty, then build reporting in their own tool of choice.

Speak to an expert

Tell us what you want to measure and we'll show you the dashboards on your own venue data.

Cluster guides in this series

Deep-dive guides that support this pillar. Each goes further on one part of measuring footfall, dwell, and visitor behaviour from WiFi. All 35 guides in this pillar are listed below.

WiFi 客流分析:如何衡量和利用访客数据

本指南为 IT 经理、网络架构师和场馆运营总监提供了一份实用、技术性的参考指南,用于在酒店餐饮、零售、活动和公共部门环境中部署 WiFi 客流分析。它涵盖了完整的数据流水线 - 从 802.11 探测请求捕获和基于 RSSI 的定位,到符合 GDPR 的数据处理和具有实用价值的商业智能仪表板。读者在阅读后将获得一个清晰的实施框架、真实世界的案例研究,以及在本季度选择、部署和优化 WiFi 分析平台所需的决策标准。

Read guide →

如何利用 WiFi 位置分析计算驻留时间

本指南为利用 WiFi 位置分析计算 WiFi 驻留时间提供了全面的技术参考,涵盖了从 802.11 探测请求捕获、基于 RSSI 的三边测量到地理围栏区域分析的完整架构。本指南专为 IT 经理、网络架构师和场所运营总监设计,旨在帮助他们在零售、酒店、医疗保健和公共部门环境中部署精准、可扩展的位置智能。读者将获得实用的实施指导、真实案例研究以及将原始空间数据转化为可衡量业务成果的清晰框架。

Read guide →

场所客流热力图分析:实用指南

本技术参考指南为在物理场馆中部署和分析基于WiFi的热力图提供了可操作策略。它解释了IT和运营领导者如何利用现有网络基础设施发现客户流动模式、消除瓶颈并优化空间投资回报率。

Read guide →

热力图 vs 客流分析:技术差异

本权威技术指南详细阐述了企业场馆运营商在 WiFi 热力图和客流分析之间的关键架构和运营差异。它为 IT 领导者、网络架构师和运营总监提供了可操作的部署框架、实际实施场景以及供应商中立的最佳实践,以从现有无线基础设施中获取最大投资回报。

Read guide →

真正对零售业重要的WiFi Analytics指标

本权威参考指南详细介绍了与零售收入、驻留时间和客户忠诚度直接相关的五大WiFi Analytics指标。它为IT经理和场所运营总监提供了一个实用框架,用于配置网络硬件、缓解MAC随机化影响,并与营销团队协调统一数据仪表盘。

Read guide →

设计隐私:为符合 GDPR 规范对 WiFi 数据进行匿名化处理

本权威指南详细介绍了用于匿名化 WiFi 数据以确保符合 GDPR 规范的技术架构和实施策略。它为 IT 领导者和网络架构师提供了切实可行的框架,以便在强大的场所分析与严格的数据隐私要求之间取得平衡。

Read guide →

人数统计:WiFi、摄像头与门禁传感器的对比

根据您需要解决的具体问题,选择最合适的人数统计技术:门禁传感器用于精确的入口总数统计,头顶摄像头用于单区域的实时人数统计,而 WiFi 则用于整个场馆的停留时间和重复访问分析。随后您可以对比精确度、成本和隐私合规工作,并结合人工计数进行试点,最终为您旗下的所有场所选择单一方法或组合方案。

Read guide →

存在分析与交互分析对比

根据您本季度需要解决的问题,决定您的场所是需要存在分析、交互分析还是两者都需要。您将了解每个层面的衡量指标、MAC 随机化如何限制存在数据、两者分别适用哪种 GDPR 合法依据,以及如何在您已拥有的接入点上,跨多个站点依序部署。

Read guide →

WiFi 7 场馆部署:体育场馆与酒店场所的基础设施就绪性指南

本操作指南可帮助场馆 IT 团队在下单订购接入点之前验证 WiFi 7 基础设施。内容涵盖 PoE、多吉比特交换、布线、控制器与许可就绪性、分析验证,以及针对体育场和酒店环境的 200 个 AP 规划模型。

Read guide →

衡量宾客 WiFi 与位置分析的业务 ROI

本技术参考指南为 IT 和场所运营团队展示了如何通过从网络健康状况、经授权的数据到经证实的运营或商业成果的可靠链条,来衡量宾客 WiFi 的 ROI。它将可衡量的证据与假设分离开来,将 Purple Connect、Capture 和 Engage 映射到正确的测量层,并为酒店、零售物业和活动场所提供了规划方案。

Read guide →

什么是 Probe Request?深入理解设备如何发现网络

本技术参考指南深入探讨了 IEEE 802.11 probe requests、主动与被动扫描以及 MAC 随机化对场所分析的影响。它为网络架构师提供了实用的实施策略,以优化高密度部署、缓解探针风暴,并确保使用认证身份层进行准确且符合 GDPR 的数据收集。

Read guide →

如何在企业无线网络上跟踪唯一设备

本指南全面介绍了在企业无线网络中跟踪唯一设备的技术概述。它针对 MAC 随机化等现代挑战,详细阐述了场馆运营商和 IT 团队如何实施策略,以维持准确的数据分析和用户身份识别。

Read guide →

Every guide in this pillar

Analytics (16)